Threat Actor
Mythic Likho
- First Reported
- Apr 2, 2026
- Latest Reported
- Apr 2, 2026
Reported Context (1)
- Group tracked attacking Russian critical infrastructure for financial extortion using tailored phishing, custom loaders, Loki, and LockBit. Researchers assess a link to (Ex)Cobalt but leave joint operations versus malware sharing unresolved. Mythic Likho Uses Sophisticated Malware and Social Engineering to Attack Russian Critical Infrastructure
Malware (6)
People (2)
Threat Actors (2)
MITRE ATT&CK (52)
Vendors (6)
Products (6)
Tools (15)
Industries (6)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.